Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-53917

Опубликовано: 17 дек. 2025
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

Affiliate Me version 5.0.1 contains a SQL injection vulnerability in the admin.php endpoint that allows authenticated administrators to manipulate database queries. Attackers can exploit the 'id' parameter with crafted union-based queries to extract sensitive user information including usernames and password hashes.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:powerstonegh:affiliate_me:5.0.1:*:*:*:*:*:*:*

EPSS

Процентиль: 9%
0.00031
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 6.5
github
около 2 месяцев назад

Affiliate Me version 5.0.1 contains a SQL injection vulnerability in the admin.php endpoint that allows authenticated administrators to manipulate database queries. Attackers can exploit the 'id' parameter with crafted union-based queries to extract sensitive user information including usernames and password hashes.

EPSS

Процентиль: 9%
0.00031
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-89